Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

9/2/2019
10:00 AM
Jonathan Couch
Jonathan Couch
Commentary
Connect Directly
LinkedIn
Twitter
RSS
E-Mail vvv
100%
0%

ISAC 101: Unlocking the Power of Information

How information sharing and analysis centers provide contextual threat information by creating communities that helps security professionals and their organizations grow in maturity and capability.

The primary function of Information Sharing and Analysis Centers, or ISACs, as stated in their charters, is to reduce risk in member organizations through improvements to prevention, detection, and response. To do this effectively, they must serve as a trusted broker in the sharing of specific information on relevant threats. This definition is important because of their relationship with two critical factors: the quality of shared information and the active participation of members of the core groups. As a trusted broker, the ISAC is the steward of both quality and quantity.

Prior to ISACs, if you weren't part of an "inner circle" of security professionals, you couldn't benefit from information being exchanged. ISACs allow relative newcomers to become instantly trusted, to a degree, so that they can get insight into the threats and security issues their peers are seeing.

With respect to quality, one of the goals of ISACs is to create a community where everyone can learn from each other through the sharing of meaningful data. When one organization is hit with malware or targeted by an adversary, everyone else will know when someone else in the group has seen this threat. Because anonymity is provided by the trusted broker, specific information can be provided to allow others to look in their own networks to see if they have also been targeted.

Trusted Broker: Achieving Critical Mass
The role of trusted broker enables information-sharing groups to achieve critical mass, thus providing quantity. Previously, sharing was only done between individuals who knew each other and had an established relationship. But this model is naturally limited in scope. When tens and hundreds of organizations are brought together and people don't know each other, the ISAC acts as the trusted broker to protect the anonymity of each organization that is sharing information, and provides a mechanism through which the information being shared is specific and relevant to the industry sector.

Ideally, ISACs are in a position to answer some of the biggest questions that nag security professionals: "What kinds of things are my peers and competitors seeing?" and "What are they doing to improve security that I may be missing and should be doing?" Many ISACs hold annual, semi-annual, or even quarterly events for their members to meet and discuss current leading practices related to security, cyber threat intelligence and sharing. Some of the best information shared takes place at live events where members can interact to discuss programs they have started, what they are doing, and how they are communicating and marketing themselves within their own organizations.

PII, Proprietary & Cross-Sector Info
Outside of these in-person opportunities, digital sharing tends to be limited to indicators and rebroadcasts of general information. Even with a trusted broker in place, organizations can be hesitant to share specific information. For the most part, these restrictions are self-imposed by legal staff within companies. Concerns range from sharing personally identifiable information (PII) or corporate proprietary information, to sharing information that was part of a breach. In truth, the only legal restrictions to sharing cyber threat information are regulatory in nature when it comes to disclosing PII. A lot of value can be gained by sharing what you know about the external threat, how it operates, the tools it uses, and (if you're bold enough) how it was able to subvert your security to be successful. None of those items involve PII and the data can be genericized enough so as not to give anyone a competitive advantage.

Another important, yet sometimes overlooked, source for specific and relevant information is cross-sector information. In the real world, threats are rarely limited to a single sector, and the way security professionals think about threats is not necessarily the way the bad guys think about targeting us. For example, an attack that targets the financial sector may very well be used to target oil and gas or energy or retail or government. ISACs have an opportunity to provide better cross-sector information so that members can proactively monitor and even prepare for these threats, depending on their risk profile and other priorities.

ISACs provide the culture, technology, and processes by which organizations can share information with other organizations. They are actively working to provide more contextual threat information by creating a community that helps individuals and their organizations grow in maturity and capability. It will be interesting to see where things stand next year. I'm optimistic that with an unwavering commitment to the role of "trusted broker," information-sharing groups will be able to deliver value at scale.

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "The Right to Be Patched: How Sentient Robots Will Change InfoSec Management."

As Senior VP of Strategy of ThreatQuotient, Jonathan Couch utilizes his 20+ years of experience in information security, information warfare, and intelligence collection to focus on the development of people, process, and technology within client organizations to assist in ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
JeffreyT450
50%
50%
JeffreyT450,
User Rank: Apprentice
9/6/2019 | 9:48:31 AM
Excellent Overview of the Power of ISACs
This is an excellent overview of the power of building a trusted community to share intelligence and best practices.
AI Is Everywhere, but Don't Ignore the Basics
Howie Xu, Vice President of AI and Machine Learning at Zscaler,  9/10/2019
Fed Kaspersky Ban Made Permanent by New Rules
Dark Reading Staff 9/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-4147
PUBLISHED: 2019-09-16
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 158413.
CVE-2019-5481
PUBLISHED: 2019-09-16
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
CVE-2019-5482
PUBLISHED: 2019-09-16
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
CVE-2019-15741
PUBLISHED: 2019-09-16
An issue was discovered in GitLab Omnibus 7.4 through 12.2.1. An unsafe interaction with logrotate could result in a privilege escalation
CVE-2019-16370
PUBLISHED: 2019-09-16
The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.